North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Denial of service Attack.

  • From: Ejay Hire
  • Date: Wed Feb 08 09:23:15 2006

Hello.

For the last couple of days we have intermittently been
experiencing a (>1gbps) denial of service attack.  I want to
apologize to anyone whose DNS servers have been (ab)used in
the attack, and let you know what is occurring.

The attacker is forging our source address on dns requests,
and the DNS reply is routing to us.  I promise, we're not
attacking your dns servers.

Please take a moment to consider implementing RPF checks to
prevent these type of forged packet attacks.

Advice is welcomed both on-list and off.

Thanks,
Ejay Hire
ISDN-Net Network Engineer